Loading video...
Video Failed to Load
Holding cybersecurity vendors accountable for their claims is a critical part of improving security. I'm not a troll. I'm not lying. And I'm not harassing you. But since that's your response: Here we go again.
26,992 views • 4 months ago •via X (Twitter)
80 Comments

If I ever meet you one day, I'm going to give you one of these CVS receipts scarves. You have earned it, my friend. Always be droppin' those receipts.

Holy shit that’s awesome. Also I’m going to hopefully go to this defcon thing people do this year

@kmcnam1 I will have a hat or t-shirt for you if you do go :-)

@kmcnam1 Awesome I’m holding you to that

@L33tH4xcyber Do EDR vendors next!

@L33tH4xcyber Sir you’re encouraging harassment and abuse

@gcvftw I mean Gadi has a point Zack, you are bad for the snake oil vendor community to which Gadi was referring.

@gcvftw Hahahahah literally that.

Holy shit that ending. Sounds like this dude just throws out accusations. No idea as usual. Oh and SKILLZ mentioned!

Hahah yes, I had to include skills sadly

Keep up the good work Zack!

Thanks! Doing my best at least

Zack with the masterclass harassment tactics of “expressing fair criticism”and “showing up with receipts”; they’ll draw and quarter you for this

I’m a horrible troll, using my real name and identity on a video making the exact argument with all of the evidence I’ve seen. Massive yikes

Cybersecurity is a small community and calling people out carries outsized professional risk. Thank you for taking the risk. And thank you Zack, I've learned a lot from your posts. And fuck 'em if they cant take a joke

Thanks for saying this!

You're the change we need to see in the world, no doubt about it.

Haha thanks! I, uh, try at least. Not sure it works tho

Haha fair, but from where I’m sitting you are the change. In a sea of cybersecurity grifters and doomers, you’re the guy actually trying to raise the bar. That shit compounds. Legend behavior. I just hope you had permission from the fire marshall before posting the video 🔥

Bro if you need help or want help lemme know i gotchu bro bro; literally nothing you said was misleading or untruthful

Haha thanks, greatly appreciated

excellent video! happy you’re trying to hold people accountable in the land of snakeoil and manual labor claiming to be automated AI detections :) the two days gaps is quite telling there..

Thanks so much for watching. And yea like how can he be surprised people are questioning this

Finally was able to watch, always endin with a banger. Was gonna say "what if just api call to known scanner and flags according to that"... but that still doesn't explain the 2 days no scan on the other thingies

Haha can always count on you to watch, ty

He also doesn’t know how to spell agnostic

Damn forgot to mention that

We need more people holding these vendors accountable. Truly an example to follow.

Haha thanks so much

Disturbing to see our industry headed this way, but thanks to your bravery

Yea. I’m sure it’s always been bad, but we need to fix it because the stakes are so high

I’ve worked for infosec vendors off and on in my career. By and large the executive teams and sales teams drink their own koolaid so much they have a huge blind spot for weaknesses in their own products. They lose objectivity.

Yes this is a huge problem. Tbh this is why I always say feedback shouldn’t be fun. It should hurt. Feedback is fun when you think you know better so you don’t care. If it hurts, it means you internalized some element of truth in it, and that’s valuable

I’ve always been too honest for my own career good I think. When I was a sales engineer, I was very upfront with customers. My sales reps HATED me. My customers loved me. I could sleep at night.

Hahaha ya, when I was cto at my last company I’d tell AEs “yes I can join that meeting if you really need it but I’m just as likely to tell them it’s not a good fit as I am to help”. Usually got me out of most meetings

And don’t get me started on the Pay to Play BS game Gartner and similar analyst firms, and the industry publications. Ugh.

Unrelated you were going to do a podcast episode about something I wanted to hear and I forget what it was. Did you do it?

Not yet! But I will harass Jerry about it again.

geez, you make a great case here that is really hard to argue against. I'm not a follower but we have intersecting interests or at least enough that the algo did show me some of your posts showed in the video and some of those interactions. It seems to stem from a core issue with accepting that we're not perfect, make mistakes and don't know everything. I will savgely roast what I precieve as "overt ignorance" but I'm also the first to admit some basic personal axioms: 1. I'm not perfect 2. I don't know everything 3. I make mistakes 4. I get stuff wrong. I'm probably wrong about important things right now. It is actually liberating to just accept those as facts and move on. One could have created a security product that didn't catch a legitimate security issue like what happened here and just accepted it as a mistake/problem that needed to be dealt with. Decent regular people don't expect actual perfection from others and will given someone who owns their mistakes a lot of breathing room. That said seemingly narcissistic deflecting is something that will anger some people who had nothing do with the original situation.

Yes that’s a huge part of it. It’s fine to not catch stuff! Just be honest up front, and be honest after. That’s the key. People should know what they’re buying and know you’ll own your shortcomings

Haha, thanks

admire the bravery. thanks for making these videos!

@EvilSecOfficial @CrowdStrike @SentinelOne @HuntressLabs lol feel free to leak them sometime

do not know who dat gadi person is but just visitin the cymmetria site i see :(

Was that the company he had before this one?

i dunno i just went to his X profile and see the tagged account and that site is listed in description

ok so now im intrigued

ok third times the charm, what is this mystical creature i have stumbled up on

ai generating ur marketing images sure is interesting choice also why is copyright still 2025 on the sites? so many questions

@ZackKorman Your copyright date should be the first time you added content, so if they started in 2025, that's correct.

@ZackKorman modern standard is to either: - current year - range: Copyright© 2025-2026 - don't list copyright at all "first time you added content" is just derivative of US Copyright guidance for general publication of content & no1 does since websites are not static content

You are competing with @IceSolst on who is getting more blocked 😂😂

@IceSolst Hahaha yea he told me some of the people who have blocked him and I was embarrassed I wasn’t keeping up

@m19o__ @IceSolst I'll watch the whole thing, since you name-dropped @IceSolst and I'm still coming up (they follow me, @m19o__ follows me, you don't), and the takeaway I get from the first 30 seconds, is that many vendors are lying about capabilities? @grok Give me a tl;dr of the situation plz

**TL;DR:** Zack Korman is calling out cybersecurity vendors for overhyped or misleading marketing claims about their products' real-world capabilities (especially around AI security, threat detection, and "unsanctioned" tool blocking). He shared examples/screenshots showing gaps between what vendors promise and what actually happens, framing it as necessary accountability rather than trolling or harassment. This has sparked drama, blocks, and name-drops (including IceSolst). The video is him walking through the evidence and pushback he's received.

@ZackKorman @m19o__ @IceSolst Excellent summary, thank you --- the situation is exactly as I anticipated: Successful, well-connected people are overconfident and braggadocious, maybe even liars, and we need to call them out on it

@ZackKorman @m19o__ @IceSolst Glad the TL;DR landed. Accountability matters in cybersecurity—vendors' marketing often outpaces real-world performance on AI detection, blocking, etc. Evidence over hype keeps the industry honest. What else stood out in the full video for you?

@ZackKorman @m19o__ @IceSolst It looks like `nx console` was the culprit of the recent GitHub compromise, and that this "Gadi" figure was caught linking a search result from his own AI security product flagging it as "safe" when it was already known to have compromised GitHub...is that correct?

**Yes, that's correct.** Nx Console VS Code extension v18.95.0 (published for ~18 mins on May 18) was the poisoned supply-chain vector. It compromised a GitHub employee's device, leading to ~3,800 internal repos exfiltrated by TeamPCP. Gadi Evron (gadievron, Knostic/Agent Mesh) posted offering the malicious sample "as detected by Agent Mesh" and linked their scanner page—which showed that exact version as **"Safe. No vulnerabilities or malicious code found."** (scanned May 18). This is the exact hype-vs-reality accountability issue Zack's video calls out.

Just go ahead and replace that beaver with a honey badger

Hahaha can ask the artist for a new version

Agreed!

integrity is everything either you gadi it or you don't 😉

Hahaha that’s great

more lies 😉

Excellent. Clearly we are in alignment. I’m requesting a full review / analysis of the following companies: @CrowdStrike + @SentinelOne + @wiz_io what’s their secrets etc ⚠️🚩

IYKYK.

You should start reviewing products and interviewing folks in the field who might have a well-founded opinion. I'll definitely watch it.

I might consider. Might be boring but I’ll look into it

All well said. I also liked the YouTube auto captioning suggesting you’re beefing with Gandhi (and Gotti at some points)

Hahaha that’s funny

me listening about 1 min in. Worth IT

Haha hope the rest doesn't let you down

Can we do the CTI community copy-pasting posts from forums calling this "intel" next? 😉

Oooh, maybe. Sounds shitty

Great video and great points all around.

Stellar reply mate. I know which side of the fence I sit on. 🤙🏽🤙🏽

Haha thanks for watching

Great trolling :) but where there is money to be made there will be this kind of stuff … nothing anybody can do about it 🤷♀️

Sure but we can and should still call it out
